<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 18:21:46 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-11998</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-11998</link>
      <description>bdu:2025-11998</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-11998</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-37915</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-37915</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-37915</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0464 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0464</link>
      <description>certfr-2025-avi-0464</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0464</guid>
    </item>
    <item>
      <title>EUVD-2026-346856</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346856</link>
      <description>EUVD-2026-346856</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346856</guid>
    </item>
    <item>
      <title>fkie_cve-2025-37915</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-37915</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net_sched: drr: Fix double list add in class with netem as child qdisc&lt;/p&gt;
&lt;p&gt;As described in Gerrard&amp;#39;s report [1], there are use cases where a netem
child qdisc will make the parent qdisc&amp;#39;s enqueue callback reentrant.
In the case of drr, there won&amp;#39;t be a UAF, but the code will add the same
classifier to the list twice, which will cause memory corruption.&lt;/p&gt;
&lt;p&gt;In addition to checking for qlen being zero, this patch checks whether the
class was already added to the active_list (cl_is_active) before adding
to the list to cover for the reentrant case.&lt;/p&gt;
&lt;p&gt;[1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net_sched: drr: Fix double list add in class with netem as child qdisc&lt;/p&gt;
&lt;p&gt;As described in Gerrard&amp;#39;s report [1], there are use cases where a netem
child qdisc will make the parent qdisc&amp;#39;s enqueue callback reentrant.
In the case of drr, there won&amp;#39;t be a UAF, but the code will add the same
classifier to the list twice, which will cause memory corruption.&lt;/p&gt;
&lt;p&gt;In addition to checking for qlen being zero, this patch checks whether the
class was already added to the active_list (cl_is_active) before adding
to the list to cover for the reentrant case.&lt;/p&gt;
&lt;p&gt;[1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-37915</guid>
    </item>
    <item>
      <title>GHSA-j8pj-vhjm-p7g6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j8pj-vhjm-p7g6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net_sched: drr: Fix double list add in class with netem as child qdisc&lt;/p&gt;
&lt;p&gt;As described in Gerrard&amp;#39;s report [1], there are use cases where a netem
child qdisc will make the parent qdisc&amp;#39;s enqueue callback reentrant.
In the case of drr, there won&amp;#39;t be a UAF, but the code will add the same
classifier to the list twice, which will cause memory corruption.&lt;/p&gt;
&lt;p&gt;In addition to checking for qlen being zero, this patch checks whether the
class was already added to the active_list (cl_is_active) before adding
to the list to cover for the reentrant case.&lt;/p&gt;
&lt;p&gt;[1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net_sched: drr: Fix double list add in class with netem as child qdisc&lt;/p&gt;
&lt;p&gt;As described in Gerrard&amp;#39;s report [1], there are use cases where a netem
child qdisc will make the parent qdisc&amp;#39;s enqueue callback reentrant.
In the case of drr, there won&amp;#39;t be a UAF, but the code will add the same
classifier to the list twice, which will cause memory corruption.&lt;/p&gt;
&lt;p&gt;In addition to checking for qlen being zero, this patch checks whether the
class was already added to the active_list (cl_is_active) before adding
to the list to cover for the reentrant case.&lt;/p&gt;
&lt;p&gt;[1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j8pj-vhjm-p7g6</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-37915 — net_sched: drr: Fix double list add in class with netem as child qdisc</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-37915</link>
      <description>msrc_CVE-2025-37915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-37915</guid>
    </item>
    <item>
      <title>OESA-2025-2054 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2054</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/vkms: Fix use after free and double free on init error&lt;/p&gt;
&lt;p&gt;If the driver initialization fails, the vkms_exit() function might
access an uninitialized or freed default_config pointer and it might
double free it.&lt;/p&gt;
&lt;p&gt;Fix both possible errors by initializing default_config only when the
driver initialization succeeded.(CVE-2025-22097)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: at76c50x: fix use after free access in at76_disconnect&lt;/p&gt;
&lt;p&gt;The memory pointed to by priv is freed at the end of at76_delete_device
function (using ieee80211_free_hw). But the code then accesses the udev
field of the freed object to put the USB device. This may also lead to a
memory leak of the usb device. Fix this by using udev from interface.(CVE-2025-37796)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;codel: remove sch-&amp;amp;gt;q.qlen check before qdisc_tree_reduce_backlog()&lt;/p&gt;
&lt;p&gt;After making all -&amp;amp;gt;qlen_notify() callbacks idempotent, now it is safe to
remove the check of qlen!=0 from both fq_codel_dequeue() and
codel_qdisc_dequeue().(CVE-2025-37798)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net_sched: qfq: Fix double list add in class with netem as child qdisc&lt;/p&gt;
&lt;p&gt;As described in Gerrard&amp;amp;apos;s report [1], there are use cases where a netem
child qdisc will make the parent qdisc&amp;amp;apos;s enqueue…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/vkms: Fix use after free and double free on init error&lt;/p&gt;
&lt;p&gt;If the driver initialization fails, the vkms_exit() function might
access an uninitialized or freed default_config pointer and it might
double free it.&lt;/p&gt;
&lt;p&gt;Fix both possible errors by initializing default_config only when the
driver initialization succeeded.(CVE-2025-22097)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: at76c50x: fix use after free access in at76_disconnect&lt;/p&gt;
&lt;p&gt;The memory pointed to by priv is freed at the end of at76_delete_device
function (using ieee80211_free_hw). But the code then accesses the udev
field of the freed object to put the USB device. This may also lead to a
memory leak of the usb device. Fix this by using udev from interface.(CVE-2025-37796)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;codel: remove sch-&amp;amp;gt;q.qlen check before qdisc_tree_reduce_backlog()&lt;/p&gt;
&lt;p&gt;After making all -&amp;amp;gt;qlen_notify() callbacks idempotent, now it is safe to
remove the check of qlen!=0 from both fq_codel_dequeue() and
codel_qdisc_dequeue().(CVE-2025-37798)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net_sched: qfq: Fix double list add in class with netem as child qdisc&lt;/p&gt;
&lt;p&gt;As described in Gerrard&amp;amp;apos;s report [1], there are use cases where a netem
child qdisc will make the parent qdisc&amp;amp;apos;s enqueue…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2054</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01964-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-37915</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37915</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 184 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net_sched: drr: Fix double list add in class with netem as child qdisc As described in Gerrard&amp;#39;s report [1], there are use cases where a netem child qdisc will make the parent qdisc&amp;#39;s enqueue callback reentrant. In the case of drr, there won&amp;#39;t be a UAF, but the code will add the same classifier to the list twice, which will cause memory corruption. In addition to checking for qlen being zero, this patch checks whether the class was already added to the active_list (cl_is_active) before adding to the list to cover for the reentrant case. [1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 184 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net_sched: drr: Fix double list add in class with netem as child qdisc As described in Gerrard&amp;#39;s report [1], there are use cases where a netem child qdisc will make the parent qdisc&amp;#39;s enqueue callback reentrant. In the case of drr, there won&amp;#39;t be a UAF, but the code will add the same classifier to the list twice, which will cause memory corruption. In addition to checking for qlen being zero, this patch checks whether the class was already added to the active_list (cl_is_active) before adding to the list to cover for the reentrant case. [1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37915</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1114 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1114</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff und weitere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff und weitere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1114</guid>
    </item>
  </channel>
</rss>
